- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-19-2022 03:16 PM
Hi there,
I'm trying to build out a config in my lab where my global protect configuration requires a machine cert and username/password for only Windows OS and MAC OS systems and then for IOS and ANDROID devices, they will only require username/password. My lab is running an old PA-5050 on PAN OS 8.1.23. I'm finding that the only option is to enable a certificate profile for ALL systems and we cannot specify specific settings based on OS.
Has anyone successfully done this?
Alternatively is it possible to configure multiple gateways on the same edge and then use the portal 'agent configuration' to redirect to different gateways that enforce different certificate profiles?
I'm also looking at options on PAN OS 9.1.X.
Thank you,
Michael
10-21-2022 11:07 AM - edited 10-21-2022 11:08 AM
Hi Michael,
The Certificate profile config is indeed for all operating systems, but at least in 9.1 the "Allow Authentication with User Credentials OR Client Certificate" setting can be configured per operating system. You could have it like this for example:
Cert profile: configured for all
OS Windows: Allow Authentication with User Credentials OR Client Certificate = NO
OS Android: Allow Authentication with User Credentials OR Client Certificate = YES
This should result in Windows needing a Client Cert + User Credentials, but Android would need only one or the other.
Your second option is also valid. You can use OS in the Config Selection Criteria of the Portal to give a different Portal config to different OS's, and those different Portal configs send them to different Gateways which have different cert profile configs.
- DM
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!